Vulnerability Description
Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of any user to any authenticated user, including students. There is no authorization check. This vulnerability is fixed in 1.11.38.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Chamilo | Chamilo Lms | < 1.11.38 |
Related Weaknesses (CWE)
References
- https://github.com/chamilo/chamilo-lms/commit/4a119f93abbfba6fe833580f2463c8d4afPatch
- https://github.com/chamilo/chamilo-lms/security/advisories/GHSA-qwch-82q9-q999Vendor Advisory
FAQ
What is CVE-2026-33708?
CVE-2026-33708 is a vulnerability with a CVSS score of 6.5 (MEDIUM). Chamilo LMS is a learning management system. Prior to 1.11.38, the get_user_info_from_username REST API endpoint returns personal information (email, first name, last name, user ID, active status) of ...
How severe is CVE-2026-33708?
CVE-2026-33708 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-33708?
Check the references section above for vendor advisories and patch information. Affected products include: Chamilo Chamilo Lms.